The Sky is Full of Secrets: Glaring Vulnerabilities Discovered in Satellite Communications

Communications from Specific Satellites
There are 590 geosynchronous satellites orbiting the earth, with a wide variety of uses, including residential television and Internet services, and in-flight WiFi. These satellites also carry traffic on private networks for sensitive, remote commercial and military equipment. By placing a large satellite dish on the top of the computer science and engineering building at the UC San Diego Jacobs School of Engineering, researchers were able to intercept communications from 39 satellites – about 15% of GEO satellites–during a seven-month period. 

GEO satellites are known to be potentially vulnerable to eavesdropping. As a result, a cottage industry has arisen to try to listen in on signals using off-the-shelf, commercially available satellite dishes. High-quality free software is available to receive satellite signals, as long as they’re not encrypted. A thriving online community of enthusiasts publishes open databases of satellite coordinates and transponders. As part of their study, researchers contributed new software that automates both scanning for satellites and decoding these signals.  

But until now, no one had tested on a large scale all the different types of satellite transmissions that can be eavesdropped on. The researchers believe their study is the most comprehensive to date of GEO satellites, their communications, levels of encryption and various communications equipment they carry. Many organizations don’t seem to realize that satellite traffic is not part of their internal network and can be captured if not encrypted, the researchers write. “There is a clear mismatch between how satellite customers expect data to be secured and how it is secured in practice,” they said. 

Examples of Vulnerabilities in U.S. Communications Systems
Researchers captured data from two companies that provide in-flight entertainment: Intelsat and Panasonic. They were able to determine which airlines and which flights the data was coming from, as well as metadata including which websites passengers were visiting. Researchers even were able to capture audio from news shows, sports and other programs passengers were watching in flight. 

In addition, other data the team decoded allowed them to find the names of vessels owned by the U.S. military together with both encrypted and unencrypted traffic from those vessels’ communication systems.

The vulnerability for cell phone communications, such as T-Mobile’s, happens when someone places a call in a remote area where the call is connected through a cell phone tower that routes  through a satellite, which then beams the call to the cellphone company. 

Phone calls can be encrypted at different levels. One layer of encryption comes into play from phone to cell phone tower and another from tower to tower. These last two layers get stripped away when a call gets transmitted via satellite, leaving the content of the call or text vulnerable if it’s not encrypted. The only way to protect call and text content is to encrypt that layer of data – this happens when making calls with Signal, or from iPhone to iPhone, for example. 

“Cell phone traffic is carefully encrypted […] between phone and tower to protect it against local eavesdroppers; it is shocking to discover that these private conversations were then broadcast to large portions of the continent, and that these security issues were not limited to isolated mistakes,” the researchers write.

Many Vulnerabilities in Mexican Communications Systems
Many of the vulnerabilities researchers found came from companies and government agencies in Mexico. That is not surprising since many of the satellites researchers could reach transmit data to and from our neighbor to the south. 

Two Mexican telecommunications companies, TelMex and WiBo, were particularly vulnerable. For both WiBo and TelMex, the data included phone numbers for parties on both sides of a phone call, as well as unencrypted voice data that would enable full reconstruction of audio for phone calls. Also, the data included information about online smartphone activity, including, for example, using TikTok and accessing Apple iCloud or Samsung’s app store. 

Researchers observed unencrypted satellite traffic from many organizations within the Mexican government, including the military, law enforcement and other government agencies.  For example, researchers were able to see the locations of aircraft and ships, as well as their repair schedules. They were also able to see personnel records for law enforcement. 

In addition, network traffic for Walmart Mexico was also not protected, giving researchers access to a wide range of data, including unencrypted internal corporate emails. Sales data were also available.

“We observe significant amounts of highly sensitive internal network traffic being broadcast unencrypted to large portions of North America. The severity of our findings suggests that these organizations do not routinely monitor the security of their own satellite communication links,” the researchers write. 

They are now planning to look at different kinds of satellites and perhaps locate antennas in different parts of the continental United States to capture a different range of satellite communications. 

The research team released the software they used for this study on Github.

Read more in Wenyi Morty Zhang et al., “Don’t look up: There are sensitive internal links in the clear on GEO satellites.”